Skip to main content

 

Cisco Meraki Documentation

Troubleshooting 1:1 NAT Rules Not Functioning After MX Installation

Overview

1:1 NAT rules may stop working after you install a Cisco Meraki MX WAN appliance. This commonly occurs after replacing a firewall with an MX, because the upstream modem or router has not updated its Address Resolution Protocol (ARP) table and requires a restart or manual clear. The upstream modem or router handles packets forwarded to the MX that are not addressed to the public IP address of the MX.

For more information on 1:1 NAT configuration on the MX, refer to the MX - Security & SD-WAN

Troubleshooting 1:1 NAT rules not functioning after MX installation

In this example, the MX replaces a third-party firewall that has active 1:1 NAT rules using multiple public IP addresses. The MX uses the IP addresses of the previous firewall and the corresponding 1:1 NAT rules.

 

1 to 1 NAT rule sample configuration showing an example configuration with multiple TCP ports allowed inbound

 

If the upstream router or modem does not have its ARP table cleared, it will attempt to send requests to the previous third party firewall MAC address. However, the MX ignores this packet if the upstream modem or router is not restarted.

Packet capture screenshot showing only ICMP requests outbound

 

Topology detailing ICMP flows with an incorrect MAC address

 

Troubleshooting steps

  1. Restart or clear the ARP table on the upstream modem or router. Once you clear the upstream device's ARP table or restart the device, ARP resolves correctly and requests forward to the MX with the correct MAC address, allowing 1:1 NAT to function. For more information on the ARP protocol, refer to ARP protocol.

 

Packet capture screenshot showing bidirectional ICMP flows on the LAN interface of the MX

 

Packet capture screenshot showing bidirectional ICMP flows on the internet interface of the MX

 

Topology detailing ICMP flows with a correct MAC address

 

  • Was this article helpful?